SUSPICIOUS — 3636477.pdf
SUSPICIOUS — 3636477.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
711d8b439180443be3595bca902018616d6a44439347bafef9c84d01d1638360 - SHA-1:
3e4c95dbc00d6018d0dbc387fdb45cc46bd4ad3b - MD5:
0eeb0402a00b6717b52c37ed86126e81 - ssdeep:
768:NgGzpDHxkR0AQ1lH87mRVsp0DY9XJLP9ZBO:uGFbUU87m8p0DY95LP9vO - TLSH:
T1D42F5CF35457DDCC7BC65B07A9F610686186C28C2036A6A4688CBA2CD4BC6FC7F51861 - Submitted as: 3636477.pdf
- File type: pdf · Size: 33200 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=fortnite%20account%20generator%20pc%20free, https://uploads.strikinglycdn.com/files/fda4168a-f296-413d-8b66-87b2ff616bea/63984197166.pdf, https://vodexekuteb.weebly.com/uploads/1/3/0/7/130776001/2021312.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=fortnite%20account%20generator%20pc%20free
- https://uploads.strikinglycdn.com/files/fda4168a-f296-413d-8b66-87b2ff616bea/63984197166.pdf
- https://vodexekuteb.weebly.com/uploads/1/3/0/7/130776001/2021312.pdf
- https://uploads.strikinglycdn.com/files/7907d74b-62ea-4343-91e3-3b29970ee412/83906318050.pdf
- https://s3.amazonaws.com/vovopafubipu/fesifapuloreziwikan.pdf
- https://rimofugu.files.wordpress.com/2020/11/71906757431.pdf
- https://davijoxo.weebly.com/uploads/1/3/4/3/134357566/1420341.pdf
- https://s3.amazonaws.com/zidenigad/the_heroes_of_olympus_the_house_of_hades.pdf
- https://tapojofam.weebly.com/uploads/1/3/4/5/134518610/5c998ff9d43.pdf
- https://s3.amazonaws.com/fosawef/70104454723.pdf
- https://uploads.strikinglycdn.com/files/30d2280f-569f-43c2-8164-6ebf59e39ea8/sight_word_stories.pdf
- https://uploads.strikinglycdn.com/files/6d687cc2-56cd-4dad-9044-a0a7a740efa4/xagozebovibisazatufowo.pdf
- https://uploads.strikinglycdn.com/files/80ae5166-d459-43b4-965b-997e20a48966/nivogofepif.pdf
- https://uploads.strikinglycdn.com/files/3f3926e5-34ac-4013-9ddf-cf91d688a8d3/94020019984.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- uploads.strikinglycdn.com
- vodexekuteb.weebly.com
- s3.amazonaws.com
- rimofugu.files.wordpress.com
- davijoxo.weebly.com
- tapojofam.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report